CVE-2022-40139

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
References
Link Resource
https://success.trendmicro.com/solution/000291528 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:trendmicro:apex_one:-:*:*:*:*:saas:*:*
cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-20 NVD-CWE-noinfo

21 Sep 2022, 18:43

Type Values Removed Values Added
CWE CWE-20
First Time Trendmicro apex One
Microsoft windows
Microsoft
Trendmicro
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:apex_one:-:*:*:*:*:saas:*:*
cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*
References (N/A) https://success.trendmicro.com/solution/000291528 - (N/A) https://success.trendmicro.com/solution/000291528 - Patch, Vendor Advisory

19 Sep 2022, 20:15

Type Values Removed Values Added
Summary Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability. Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

19 Sep 2022, 18:33

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-19 18:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-40139

Mitre link : CVE-2022-40139

CVE.ORG link : CVE-2022-40139


JSON object : View

Products Affected

microsoft

  • windows

trendmicro

  • apex_one